SecAudit · non-invasive · live results
Know what is open on
your site before anyone else does.
SecAudit points 11 check families at your website, IP, repo or app. Every finding re-verified, ranked, and shipped with a fix prompt your dev agent can run.
live simulation · muted · 36 s loop
3 audits free per 24 hours · ~1 minute to results · nothing installed
Live simulation · 36 seconds · on a loop
Watch the scanners work.
Target acquired, every engine lights up, findings get ranked and re-verified, grades land, the fix prompt copies itself. A full scan, compressed into half a minute.
This is a simulation. The real thing takes about a minute — and scans what you actually deployed.
You find out from someone else.
A researcher, a bot, or a breach report, weeks after the exposure started.
Every tool cries wolf.
Unverified findings pile up. You stop reading, or you fix the wrong things first.
Knowing is not fixing.
A report nobody can act on is just anxiety with a PDF attached.
This is what verified looks like.
A scanner you can trust enough to act on, because every claim is re-checked before you read it.
11 check families, one report.
Headers, CSP, TLS, exposed files, ports, email spoofing, repo secrets, AI code review, SEO / GEO / performance, letter grades — and Auto QA behind the scenes, all in a single pass, ranked by severity instead of alphabetized.
Nothing ships unverified.
Every finding is re-probed independently and judged by a skeptical verifier, then labeled honestly: verified, heuristic, or manual check.
A fix prompt, not homework.
Every report ends with a copy-paste prompt for your coding agent, priority-ordered, with working rules and acceptance criteria, plus a compare token to prove it worked.
11 check families. One report.
Pick a target, pick a scanner, get findings ranked by severity, not alphabetized by tool.
HTTP headers
highHSTS, Server/version leaks, X-Content-Type-Options, clickjacking, Referrer-Policy, cookie flags, open-redirect probes.
CSP lint
highZAP-equivalent rules: missing default-src fallback, wildcards, unsafe-inline / unsafe-eval, frame gaps.
TLS config
mediumCertificate expiry, TLS 1.0/1.1 still enabled, self-signed certs: the stuff browsers quietly punish.
Sensitive files
critical.git/HEAD, .env, .next/BUILD_ID, wp-login, /server-status, /metrics, with 404-baseline aware probing.
TCP ports
mediumFixed port list for websites, optional top-1000 sweep for IPs. Anything open beyond 80/443 gets flagged.
Repo secrets
criticalGitHub audits: AWS / Slack / OpenAI-style tokens, private key blocks, tracked .env files, old dependency floors.
AI code review
highA senior-reviewer AI reads key source files: logic, error handling, auth boundaries, injection risks. Blocking / important / nit notes with file references and a verdict.
SEO · GEO · Performance
optimizationGEO score for AI-answer visibility (ChatGPT, Claude, Perplexity, Gemini), classic SEO grading, live-measured TTFB / load / weight, robots + sitemap.
Email spoofing protection
highYour domain’s public SPF, DMARC, DKIM and MTA-STS records — can phishers send email that looks like it comes from you? Graded, with the exact DNS fixes.
Letter grades & share links
optimizationEvery website audit opens with A+ to F grades per layer — headers, TLS, exposure, ports, email. One click turns the report into a read-only link that expires in 72 hours.
Anti AI-Slop review
mediumDoes your site read as AI-generated? A 0-100 slop score, screenshots of every flagged element — each one explained and given a fix — plus a what-to-keep list and an unslop direction.
The ten-second read,
then the receipts.
Website audits open with letter grades per layer. Every grade maps to named findings underneath — no mystery deductions, ever.
A+
Overall
A-
Headers
B
TLS
C+
Exposure
A
Ports
F
An F in email is the one most sites carry without knowing it: no DMARC, so anyone can send email that looks like it comes from your domain. The audit hands you the exact records to publish.
Share report
Hand over the full picture. Then let it disappear.
One click turns a finished report into a read-only link — grades, findings, fix prompt. It works for 72 hours, deletes itself, and nothing is stored unless you press Share. Your developer gets context; the internet gets nothing.
Copy as Markdown
Paste it where the work happens.
The whole report — findings, severities, fixes, the dev-agent prompt — as clean Markdown for your tracker, your ticket or your AI coding agent. No screenshots to squint at.
A scan you can read in a minute.
Non-invasive by design: normal requests and plain TCP connects. No payloads, no exploitation.
$ xshredo scan your-site.com
→ headers … verified · 1 finding
→ csp lint … verified · 0 findings
→ tls config … verified · TLS 1.1 still enabled
→ sensitive files … critical · /.git/HEAD reachable
→ second pass: re-probing live target … confirmed
✓ 1 verified finding · fix prompt attached
Labeled, not inflated.
Heuristic does not mean wrong. It means context decides, and we tell you which.
An independent second request re-probed your live target, then a skeptical AI verifier agreed. A CDN edge hiccup cannot pose as a finding.
Context decides. Real signal, but it depends on your setup. The reasoning is one click away on every finding.
Needs a human decision. We label it rather than inflate it. If the verifier is unavailable, findings are marked unverified, never silently passed.
What you can scan.
Websites
Any public hostname or URL: the full non-invasive web audit, about 15-25 requests.
Public IPs
IPv4/IPv6, with an optional top-1000 TCP port sweep.
GitHub repos
Public repos directly; private ones with a read-only token held in memory for one scan.
Any page
A single URL for a full SEO / GEO / performance report with code-level fixes.
Your code
AI code review over sampled source files, with secret-shaped strings redacted before anything leaves.
Same question. Better answer.
What “is my site safe?” actually looks like, depending on who you ask.
| Compare | Never checking | Manual / DIY | xShredo SecAudit |
|---|---|---|---|
| What it is | You hope nothing is open | A checklist you run by hand | 11 check families, live, ranked |
| False positives | none labeled honestly | Every tool, every time | Second-pass verification, labeled |
| Repo secrets | Discovered by luck | Manual grep, when you remember | Token, key and .env patterns |
| AI code review | Whoever noticed first | A week of your time | Minutes, with file references |
| Getting it fixed | Panic + guesswork | Paste errors into a chat | A ready-to-paste fix prompt |
| Tracking progress | No idea | A spreadsheet | Compare token: fixed / open / new |
Free tier. Every scanner.
3audits / 24h
Free, no card. Deep scans, fast, unmolested, so each one is worth reading.
Need more? Scan tokens for teams and CI pipelines, sized to your volume.
Included free
- All 11 scanners
- Second-pass verification
- Ranked severity report
- Copy-paste fix prompt
- Compare token for progress
What you pay later
- Nothing, if 3 a day is enough
- Scan tokens for CI or client work
- Sized to your actual volume
What you are not paying for
- Per-finding fees
- Sales calls about your findings
- Setup, agents, or onboarding
- A retainer to keep watching
Questions, answered.
Is the scan safe for my site?
Yes. Non-invasive by design: normal HTTP(S) requests and plain TCP connects only. No exploitation, no payloads, no DoS. A web audit sends roughly 15-25 requests total, and redirects to other hosts are observed but never followed. Only scan assets you own or have written permission to test.
What do you do with my GitHub token?
If you paste one, it lives in server memory for the duration of a single shallow clone, is never logged, never stored, and is scrubbed from every byte we send back. When the audit ends it is gone. Open repos need no token at all.
What leaves my repository during a code review?
Up to eight source files (a bounded sample, code files only) are sent to the AI analyst so it can reason about your code. Before anything leaves the server, secret-shaped strings are redacted, and files flagged for secrets are excluded from sampling entirely. Nothing is stored after the report is delivered.
Are the findings actually verified?
Yes. Before a report ships, every finding goes through a second pass. High-risk website checks (headers, TLS-adjacent probes) are re-confirmed with an independent second request against your live target. Every finding is then judged by a skeptical AI verifier and labeled ✓ verified, ~ heuristic or ? manual check, with a one-line reason.
How do I get the issues actually fixed?
Every report ends with a “Fix it with your dev agent” block: a ready-to-paste prompt with the full issue list in priority order, concrete fixes, working rules (rotate leaked credentials, close root causes, keep changes behavior-compatible) and acceptance criteria. Copy it into Cursor, Claude Code, Codex or Copilot, let it patch, then re-run the same audit to confirm.
Can I track progress between scans?
Every report ends with a compare token, a short checksummed string encoding which checks failed and how severely. Paste it on your next scan of the same target and the report opens with a comparison: what got fixed, what is still open, what is new, and whether your score moved. Nothing is stored on our side; if you lose the token, the history is gone.
What do the letter grades mean?
Website audits open with A+ to F grades — overall, headers, TLS, exposure, ports and email. They are pure math on the verified findings: a critical finding costs 34 points, a high one 22, a medium 12, a low 6. A+ means nothing worth flagging in that layer; F means an attacker’s checklist is wide open. Fix the findings and the grades move on your next scan — the compare token proves it.
How does Share report work?
Press Share report on any finished website audit and you get a read-only link to that exact report — grades, findings, fix prompt. The link works for 72 hours, then the snapshot deletes itself automatically. A report is only ever stored when you press Share; share nothing and nothing is kept. It is the fastest way to hand your developer, your boss or a client the full picture.
Why should I care about email spoofing?
Because anyone can send email that looks like it comes from your domain unless three public DNS records say otherwise: SPF (which servers may send), DKIM (cryptographic signing) and DMARC (what receivers should do with forgeries). The website audit reads those records — the same ones every mail server reads — grades them and hands you the exact records to publish. Most domains fail this check without knowing it.
Can the scanners touch anything else on my servers?
No. Every scanner process runs as a dedicated unprivileged account with no shell access, no read access to application files, configuration or data, and a firewall rule set that refuses all traffic to private networks, the host itself and cloud-metadata addresses. Only public internet destinations are reachable from the sandbox.
What does the operator store about my scans?
As little as the product can run on. Your report is assembled in server memory, delivered to your browser and then gone: no findings, no report content, no tokens, no contact data. What is kept is a minimal ops record per scan (time, type, target host, outcome, severity counts, duration, how it was paid) for capacity planning and abuse prevention.
How much does it cost?
The free tier is 3 audits per 24 hours; that keeps each scan deep, fast and unmolested for everyone. For teams, CI pipelines and client work, order additional scan tokens by emailing sales@xshredo.com with your expected volume and we will size it to your workflow. Some tokens are limited to specific kinds (a website-only token covers website audits but not the others).
Three free audits.
Then stop guessing.
Non-invasive · verified twice · fix prompt included · scan only what you own